Calendar

wine: updated to 1.9.23. The package contains a version of wine whose functionality has been extended by applying the 'wine-staging' and 'd3d9' (aka wine-nine, only for Slackware 14.2 and newer) patch sets. The package is so big because it also contains the MSI installers for gecko and mono, so that those won't have to be […]

Here is KDE 5_16.11 for Slackware, consisting of the KDE Frameworks 5.27.0, Plasma 5.8.3 and Applications 16.08.2 on top of Qt 5.7.0. Upgrade from the previous KDE 5_16.08 should be smooth. Please read the accompanying README file for detailed installation and upgrade instructions! Use only the "latest" repositories and not "testing" which is out of […]

Meta

LibreOffice 4.2.3 – addresses Heartbleed vulnerability

Last week was a black page in Open Source security with the publication of the Heartbleed vulnerability. For those of you who think the hype is overrated and no one will be able to get at your private keys and passwords, better check out the results of the Cloudflare Challenge (the SSL certificate for that site has been revoked in order to stop it from being abused so that page won’t load). Cloudflare’s security engineers were unable to exploit the vulnerability and retrieve their server’s private key so they confidently made it a public challenge… and at least three people independently obtained the server’s private key through the exploit! Proof was given by posting messages signed with that same private key. Read all about it on the Cloudflare blog. Don’t take this vulnerability too lightly! Slackware 14.0, 14.1 and -current users should apply the openssl patch packages as soon as possible. And if your machine was exposed to the Internet, running a secure web server (https://) then it is wise to revoke your SSL certificate and create a new one. It may also be a good idea to change the passwords of the accounts on that server.

Not just OpenSSL-protected web sites are affected; regular “client” software can be abused by attacks when these applications contain the vulnerable code because they statically link to the openssl library. I’ll post some more later, but here is the first fix:

The Document Foundation added a fix for Heartbleed to their latest LibreOffice 4.2.3 (codenamed ‘Fresh’) release. It took an additional day for me to get rid of the bugs in my revised SlackBuild script, because I had decided to split the “big” libreoffice package in three sub-packages. The SDK documentation (several hundreds of MB) has now moved into a separate package “libreoffice-sdkdoc” which you will not need unless you are a developer. And the KDE integration libraries have been moved into their own package as well: “libreoffice-kde-integration”. It’s these libraries which give the LibreOffice user interface the “KDE look” when you are running KDE, and make it use the KDE file dialogs. Some people experienced issues in KDE which were solved by removing these KDE libraries, and the new sub-package was born to help you get a better experience out of LibreOffice on Slackware. Note that if you are on KDE and simply “upgradepkg” the libreoffice package, your application will suddenly look very out of style, having switched to a GTK look & feel. All you need to do is “installpkg” the new libreoffice-kde-integration package.

If you are in need of stability, note that the official statement from the Document Foundation is that LibreOffice 4.2.3 is “the most feature rich version of the software, and is suited for early adopters willing to leverage a larger number of innovations. For enterprise deployments and for more conservative users, The Document Foundation suggests the more mature LibreOffice 4.1.5“. You can find Slackware packages for LibreOffice 4.1.5 in my repository onder the “14.0”directory. They were built on Slackware 14.0 and work well on Slackware 14.1 and -current.

Packages for Slackware 14.1 and -current are ready for download from the usual mirror locations:

That’s weird. I have the same problem just now. I installed the LibreOffice 4.2.3 package on a Slackware 14.1 computer and my Slackware-current laptop and all was well. I am now working at my Slackware-current desktop and on this machine, I see the outline of the Writer window appear and then it freezes.

Looks like this bug: https://bugs.freedesktop.org/show_bug.cgi?id=77128
Too bad that the fix is already in the repository, they just failed to back-port it to the 4.2 branch.
I am test-compiling KDE 4.13.0 at the moment which takes all my time, after that has finished I will see if I can patch the LibreOffice package.

Eric

Comment from RichardPosted: April 14, 2014 at 07:34

Hi, Eric.

I am the issue with LIbreOffice Writer, when I try to open a .odt file from LibreOffice, It quits without any message, the same thing happens when I export a file as pdf.